4site develops a content management system product that exhibits a durable pattern of SQL injection vulnerabilities, a critical input-handling weakness affecting application-tier security. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 4site over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4152HIGH SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: t | Nov 3, 2010 | 7.5 | 32 | NO | YES |
CVE-2009-0646HIGH Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4 | Feb 18, 2009 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 4site.
Media articles that mention a CVE ID that affects a product developed by 4site — matched by CVE ID, not by vendor name.